Red Hat Security Advisory: freerdp security update
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-55192 — FreeRDP: FreeRDP: Out-of-bounds read leads to memory disclosure or client crash CVE-2026-55194 — FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response CVE-2026-67288 — FreeRDP: FreeRDP: Denial of Service via crafted smartcard cache requests CVE-2026-67290 — FreeRDP: FreeRDP: Denial of Service via malformed media data CVE-2026-67291 — FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read CVE-2026-67298 — FreeRDP: FreeRDP: Denial of Service via integer underflow in RAIL channel handling CVE-2026-67301 — FreeRDP: FreeRDP: Memory disclosure or denial of service via crafted RDP update orders
🎯 Affected products49
- Red Hat Enterprise Linux Server (v. 7 ELS)
- Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-0:2.1.1-5.el7_9.12.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-0:2.1.1-5.el7_9.12.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-0:2.1.1-5.el7_9.12.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-0:2.1.1-5.el7_9.12.src as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-0:2.1.1-5.el7_9.12.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc64le as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.s390 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.s390 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.s390x as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.x86_64 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-debuginfo-0:2.1.1-5.el7_9.12.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.i686 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.ppc as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.ppc64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.ppc64le as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.s390 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.s390x as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-devel-0:2.1.1-5.el7_9.12.x86_64 as a component of Red Hat Enterprise Linux Server Optional (v. 7 ELS)
- freerdp-libs-0:2.1.1-5.el7_9.12.i686 as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- freerdp-libs-0:2.1.1-5.el7_9.12.ppc as a component of Red Hat Enterprise Linux Server (v. 7 ELS)
- +19 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this vulnerability, disable H.264 graphics acceleration in client connection parameters (e.g., omitting `/gfx:avc420` or `/gfx:avc444` in `xfreerdp`) to force legacy RemoteFX or standard software bitmap rendering. Workaround: To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing. Workaround: If smartcard redirection/emulation is unused, do not enable it (omit /smartcard and /smartcard-logon, or start with /smartcard:off). Only connect FreeRDP clients to trusted RDP endpoints Workaround: To mitigate this issue, disable the Terminal Services Multimedia Redirection (TSMF) feature when connecting to untrusted RDP servers. This prevents the vulnerable media processing from being engaged. For `xfreerdp` clients, use the `/disable-tsmf` or `/tsmf:off` command-line option: `xfreerdp /disable-tsmf <server_address>` Disabling TSMF will prevent multimedia content from being redirected during the RDP session. Workaround: To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads. Workaround: To mitigate this issue do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused. Workaround: To mitigate this issue, avoid enabling the `async-update` feature when using FreeRDP clients. This feature is not enabled by default. If `xfreerdp` is used, ensure the `/async-update` command-line option is not specified. Disabling this feature may impact performance in certain RDP sessions where asynchronous updates are beneficial.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:68707
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509984
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2509994
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510001
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510010
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510041
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519823
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2519824
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68707.json